fix: device code flow maybe (#158)

This commit is contained in:
Antoine Lecompte
2026-06-26 13:58:11 +00:00
committed by GitHub
parent 9f7b94b5fb
commit ec750767a3
4 changed files with 10 additions and 2 deletions
+2
View File
@@ -26,6 +26,8 @@ export TF_VAR_flux_github_app_private_key="op://shared_tf/GITHUB_APP_IMMICH_PUSH
# ─── staging/talos secrets (secrets.tf) — env-specific, in yucca_tf_staging ──
export TF_VAR_yucca_oidc_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID/password"
export TF_VAR_yucca_oidc_client_secret="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_SECRET/password"
# Public device-flow client id (manually copied from yucca_tf_dev for now).
export TF_VAR_yucca_oidc_device_client_id="op://yucca_tf_staging/CUSTOMER_ZITADEL_OAUTH_CLIENT_ID_DEVICE/password"
# admin-api OIDC client not registered yet (admin-api is in-cluster-only).
# export TF_VAR_yucca_oidc_admin_client_id="op://yucca_tf_staging/.../password"
# export TF_VAR_yucca_oidc_admin_client_secret="op://yucca_tf_staging/.../password"
+1 -1
View File
@@ -119,7 +119,7 @@ resource "kubernetes_secret_v1" "yucca_api" {
JWT_PRIVATE_KEY = tls_private_key.yucca_jwt[0].private_key_pem_pkcs8
OIDC_CLIENT_ID = var.yucca_oidc_client_id
OIDC_CLIENT_SECRET = var.yucca_oidc_client_secret
OIDC_DEVICE_CLIENT_ID = var.yucca_oidc_client_id
OIDC_DEVICE_CLIENT_ID = var.yucca_oidc_device_client_id
}
}
+7
View File
@@ -57,6 +57,13 @@ variable "yucca_oidc_client_secret" {
default = ""
}
# Device-flow client: separate PUBLIC client (no secret), DEVICE_CODE grant.
variable "yucca_oidc_device_client_id" {
description = "Public OIDC client ID for yucca-api's device flow. Injected via TF_VAR from 1P."
type = string
default = ""
}
# yucca-admin-api OIDC client (separate registration from yucca-api).
variable "yucca_oidc_admin_client_id" {
description = "OIDC client ID for yucca-admin-api (staging IdP). Injected via TF_VAR from 1P."